[22204] in Kerberos

home help back first fref pref prev next nref lref last post

keytab vs database

daemon@ATHENA.MIT.EDU (Lara Adianto)
Tue Aug 17 05:31:01 2004

Message-ID: <20040817092737.66342.qmail@web50202.mail.yahoo.com>
Date: Tue, 17 Aug 2004 02:27:37 -0700 (PDT)
From: Lara Adianto <m1r4cle_26@yahoo.com>
To: kerberos@mit.edu
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Errors-To: kerberos-bounces@mit.edu

Hi,

I have a basic question about kerberos concept.
As I browsed through MIT source code to better
understand how kerberos works, I noticed that in
processing the tgs request, the ticket is always
decrypted using server's key retrieved from keytab. If
the server is a TGS service (krbtgt) or
kadmin/changepw which are part of a KDC (am I right to
say this ?), is it okay to retrieve the key from the
database instead of from the keytab ? 

Does a KDC need to maintain a keytab actually ?

thank you,
lara

=====
------------------------------------------------------------------------------------ 
La vie, voyez-vous, ca n'est jamais si bon ni si mauvais qu'on croit
                                                                        - Guy de Maupassant -
------------------------------------------------------------------------------------


		
__________________________________
Do you Yahoo!?
Y! Messenger - Communicate in real time. Download now. 
http://messenger.yahoo.com
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post